CVE-1999-0440: High severity Netscape Navigator vulnerability
The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Javafrom your environment.Uninstall or remove the Java runtime / Java browser plugin from systems where it is not required to eliminate the vulnerable byte code verifier component.
- Configuration
Disable Java (the Java plugin / applet execution) in the browser settings for Netscape Communicator and Netscape Navigator to prevent execution of untrusted bytecode from web pages.
Netscape Communicator / Netscape Navigator Java applet / Java plugin enabled = false - Compensating control
Restrict or filter access to untrusted or potentially malicious web pages (for example via firewall rules, web proxy URL filtering, or a web application firewall) to prevent delivery of malicious Java bytecode to users.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0440?
CVE-1999-0440 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-1999-0440?
To fix CVE-1999-0440, upgrade to the latest version of the affected software that addresses this vulnerability.
What software is affected by CVE-1999-0440?
CVE-1999-0440 affects various versions of Netscape Navigator and Sun Java.
Can CVE-1999-0440 be exploited remotely?
Yes, CVE-1999-0440 can be exploited remotely through malicious web pages.
What is the impact of CVE-1999-0440?
The impact of CVE-1999-0440 includes the ability for attackers to execute arbitrary code on the affected system.